U.S. Congress advances AI and cyber bills
Congress is weighing bills on AI chatbots, autonomous agents, maritime cybersecurity and health care resilience, with compliance implications.
The U.S. Congress is moving several bills that touch maritime cybersecurity, privacy in AI chatbots, autonomous agent controls, and health care resilience. They include S.4564, H.R.9619, the Stop Rogue AI Act, and a bill to strengthen health sector cybersecurity.
The U.S. Congress is moving several bills that touch maritime cybersecurity, privacy in AI chatbots, autonomous agent controls, and health care resilience. They include S.4564, H.R.9619, the Stop Rogue AI Act, and a bill to strengthen health sector cybersecurity. Together, these proposals could end up serving as new compliance frameworks for Latin American subsidiaries and operations exposed to those sectors.
What does the maritime bill S.4564 aim to do?
S.4564, the Maritime Cybersecurity Act, seeks to have the U.S. Coast Guard assess cybersecurity risks tied to the software and hardware used in maritime settings. The text also includes confidentiality provisions for information collected under section 552(b)(3) of the U.S. Code, according to the version moving through the Senate.
The measure is part of the 119th Congress, covering 2025 to 2026, and remains under debate in the upper chamber. Because of its scope, it introduces a risk assessment approach to operational technology and systems used in maritime activity, a sensitive issue for shipping companies, port operators, and logistics chains with a regional footprint.
What changes for AI chatbots?
H.R.9619 would require providers of artificial intelligence chatbots in the United States to ensure data privacy and security. The official legislative summary describes it as a specific federal bill on data protection and cybersecurity for conversational AI services.
The bill is also part of the 119th Congress package, under consideration during 2025 and 2026. For companies that operate across borders from Latin America or provide services across borders, the key point is that the debate is no longer limited to AI models in the abstract, but to direct obligations for providers of conversational tools.
What does the Stop Rogue AI Act require?
The Stop Rogue AI Act would direct NIST to develop standards, guidance, and best practices to detect, verify, and control AI agents, and would require federal contractors and agencies to build those safeguards into the procurement and deployment of those systems. Implementation would be done in coordination with CISA.
According to Mike Lawler's office, the bill aims to ensure standards do not rely only on self-certification or on claims from a single vendor to establish an agent's identity. It also includes baseline organizational requirements on how agents are deployed and authenticated in federal systems.
Josh Gottheimer's office added that the technical specifications would need to include continuous, machine-readable inventories of all AI agents, identity and provenance verification, real-time monitoring for anomalous behavior such as prompt injection and data theft, and the ability to revoke access and actions at a granular level.
Coverage from Forkast, Techstrong.ai, and Integrated.social describes the measure as the first federal bill specifically intended to impose NIST-based security standards for AI agents. Those reports also say the agency would have one year from any enactment to issue secure deployment guidance and best practices, with machine-readable inventories, tamper-resistant logs, continuous monitoring, and reliability assessments.
Quasa.io adds that, in its current form, the bill remains unapproved and that NIST's future standards would be mandatory mainly for federal agencies and contractors, while for many private organizations they would initially function as voluntary adoption frameworks, though they could become a sector compliance reference.
What is happening in health care?
The Health Care Cybersecurity and Resiliency Act of 2025 has been introduced in the U.S. Congress, but according to IEEE it has not yet been approved. The goal is to strengthen cybersecurity in the health sector through funding, incentives, and updates to regulatory frameworks in response to the rise in data breaches and ransomware attacks on health organizations.
That bill broadens the regulatory debate beyond AI and maritime transport to a sector already under pressure from information theft incidents and the need to modernize controls, especially across care networks and connected services.
Sources
- Telehealth & Cybersecurity Threats: What to Knowstandards.ieee.org· IEEE Standards Association
- H.R.9917 - AI Kill Switch Actcongress.gov· Congress.govUnverified URL
- Bipartisan House Bill Targets Rogue AI Agents Following High-Profile OpenAI Breachestechstrong.ai· Techstrong.ai
- Stop Rogue AI Act: Enterprise Agent Security (2026)integrated.social· Integrated.social
- Stop Rogue AI Act、AI台帳を連邦請負要件へquasa.io· Quasa.io
- S.4564 - Maritime Cybersecurity Act, 119th Congress (2025-2026)congress.gov· Congress.govUnverified URL
- H.R.9619 - To require artificial intelligence chatbot providers to provide data privacy and security, and for other purposescongress.gov· Congress.govUnverified URL
- Gottheimer Introduces Bipartisan Bill to Stop Rogue AI Agents and Keep People in Controlgottheimer.house.gov· U.S. House of Representatives
- Inside AI Policy: Gottheimer-Lawler bill rejects self-attestation alonelawler.house.gov· U.S. House of Representatives (Office of Rep. Mike Lawler)
- Congress Is Building the Scaffolding: The First Federal Bill Mandating Agent Security Standardsforkast.news· Forkast



